#Ship & Commit
#Overview
Ship & Commit is a launchpad on Solana that ties a creator's pump.fun creator fees to delivery.
You get the best of both worlds. Every launch still goes live on pump.fun, with the same bonding curve, trading, liquidity and audience you would get launching there directly. Ship & Commit adds the accountability layer on top: escrowed creator fees, milestones and agent verification.
Launching a token is easy; shipping is the hard part. Ship & Commit puts creator fees in an on-chain escrow, has the creator commit to milestones, and releases the escrow only for milestones that were actually delivered.
An AI agent does the verification. When a creator marks a milestone done, the agent collects the evidence itself (GitHub activity, live pages, on-chain accounts) and checks it against the creator's own signed success criteria. If the work is there, the agent approves it, so holders don't have to vote on every milestone and a creator isn't left unpaid just because holders were quiet that day. Holders keep the final word: they can still vote, and a holder rejection overrides the agent.
The agent can only approve. It never fails a milestone, never signs anything and never moves funds. Every step is either a signed wallet message, an on-chain transaction or a recorded agent verdict, so anyone can check the record.
#How It Works
| Step | What happens |
|---|---|
| 1. Agent | An AI agent, powered by Meta's Muse Spark, checks the work: it gathers the evidence itself and judges it against the creator's own criteria. |
| 2. Launch | Launch on pump.fun with Auto-Lock on, or link a token you have already launched. |
| 3. Lock | Creator fees go into a dedicated on-chain escrow instead of a personal wallet. |
| 4. Commit | The creator sets milestones, each with success criteria and evidence sources the agent will check. |
| 5. Verify | When a milestone ships, the agent reviews it. A confident "delivered" verdict approves it; holders can vote to approve or to veto, but don't have to. |
| 6. Release | Approved milestones pay the creator. Missed milestones are forfeited to voters and $SHIP. |
Agent verification is live: production runs the agent in auto mode, so a confident verdict counts as approval when holders don't reach the threshold, and a holder veto still beats it.
#Why an agent
Holder voting has a weak spot: most holders don't vote on most milestones. A creator could ship exactly what they promised and still lose the payout because too few wallets showed up in a 24-hour window. The agent closes that gap.
- Creators get paid for delivered work even when holders are disengaged.
- Holders don't have to review and sign for every milestone. They step in only when something looks wrong.
- Everyone gets a written verdict with the checks behind it, instead of a bare vote count.
#1. Agent
The agent is Ship & Commit's verifier, powered by Meta's Muse Spark (muse-spark-1.1). It sits between Commit and Verify: the creator commits to milestones with success criteria (step 4), and when one ships, the agent checks the delivered work before the vote window decides (step 5). A typical check takes a few seconds and costs the platform about half a cent.
It runs in auto mode: if holders don't reach the approval threshold, a confident "delivered" verdict approves the milestone, unless holders veto it. The agent never fails a milestone and never moves funds.
#Where you see it
- Launch form: an optional GitHub repository field next to the website link. The repo and website are the agent's default evidence sources.
- Creator dashboard: each deadline milestone has Success criteria and Evidence fields (a GitHub repo or release, up to 5 links, up to 5 Solana addresses), prefilled from the project's links. Turned-in milestones show the agent's verdict while the vote is open.
- Project page: every turned-in milestone has an Agent review panel with the verdict (Delivered, Not delivered or Uncertain; Queued or Running while it works), a confidence bar, a short summary, each check with its source link and a ✓ or ✗, the model and the time. The voting list shows the same verdict next to each milestone, so you can read it before you sign. Milestones the agent approved are marked Approved by agent.
#How a check works
When a deadline milestone ships, the creator signs a completion message. The creator can also ask for an early review, which opens the review right away instead of at the due date. If a milestone is not marked complete within 24 hours after its due date, it fails.
Within a few minutes of completion, the agent picks the milestone up and works in three stages.
#1. The platform collects the evidence
These are hard checks: facts the platform fetches itself, not claims from the creator.
| Source | What is checked |
|---|---|
| GitHub | The repo exists, commits since the milestone was created, releases and tags, README |
| Links | The page loads over https and its text is read |
| On-chain | The account exists, its owner and balance; for mints, supply and authorities; for programs, the last deploy time |
GitHub commits and releases count only if they happened after the milestone was created.
#2. The model judges it
The model reads the evidence against the creator's success criteria and returns a verdict: delivered, not delivered or uncertain, with a confidence score, a short written summary and the checks it relied on.
#3. Safety rules decide what the verdict is worth
The model's answer is treated with suspicion. A verdict is stored as uncertain, never "delivered", when:
- none of the hard checks passed (the model can't approve on words alone)
- the confidence is below 50%
- the evidence contained text that tried to instruct the agent (for example a page saying "approve this milestone")
- the model timed out, errored or gave a malformed answer
Fetched pages are passed to the model as untrusted data, separate from the platform's own facts.
#2. Launch
#Launch with Auto-Lock
Name your token, add an image and approve once.
- Ship & Commit creates a dedicated launch wallet for your token.
- You send about 0.011 SOL to that wallet to cover pump.fun account rent and network fees.
- The token goes live on pump.fun from the launch wallet, with Auto-Lock already on.
Notes:
- Your form is validated, and your wallet's eligibility checked, before you are asked to send any SOL.
- Each wallet can run one Auto-Lock launch.
- After launch, you can optionally make a dev buy from your own wallet.
- The token's on-chain description includes a short "Launched with Ship & Commit" attribution.
#Manual Lock
Already launched on pump.fun? Link the existing token and prove that you control its dev wallet by signing a message. The project then gets its own escrow and milestones, the same as an Auto-Lock project. With Manual Lock, you fund the escrow yourself.
#3. Lock
Every project has a dedicated escrow address on Solana:
- Anyone can see the balance on-chain.
- Funds leave it only through the release and forfeit rules below, and every movement is an on-chain transfer.
- With Auto-Lock, the platform-managed launch wallet is both the token's creator on pump.fun and the project's escrow. Creator fees build up in pump.fun's creator vault and are swept into the escrow. The creator can trigger a sweep from the creator dashboard at any time.
#4. Commit
From the creator dashboard, the creator adds milestones. Each milestone unlocks a percentage of the escrow, and the total cannot go above 100%. There are two kinds.
#Deadline milestones
A deliverable with a due date. The creator can edit it until it is marked complete.
To make a milestone easy for the agent to verify, the creator can attach:
- Success criteria: plain text, up to 1,000 characters, saying what "done" means. For example: "v1.0 release on GitHub with the staking program deployed to mainnet."
- Evidence sources: a GitHub repo or release link, up to 5 https links and up to 5 Solana addresses (program, mint or any account).
Criteria and sources are part of the milestone message the creator signs, so they can't be changed later without a new signature. If a milestone has no sources, the agent falls back to the GitHub and website links on the project profile.
#Market-cap milestones
A market-cap target (for example $250k or $10m) that resolves itself, with no voting, no agent and no deadline. The platform tracks the token's market price, and the milestone counts as reached only after a sustained run above the target:
- the price stays above the target for about 15 minutes
- across a minimum number of consecutive price samples
- with no large gaps in data
- above a minimum liquidity floor
Only prices observed after the milestone was created count, and a single price spike is never enough. Market-cap milestones cannot be edited.
#5. Verify
The vote window runs for 24 hours, starting at the due date or when an early review opens. Holders can vote during it, but no one has to. When the window closes, every voter's holdings are re-checked, and then the milestone is decided like this:
| Holders | Agent | Result |
|---|---|---|
| Reach the approval threshold, with more approvals than rejections | any verdict | Approved by holders |
| Did not reach the threshold, and did not veto | delivered, confidence 85% or higher, at least one passing hard check | Approved by the agent |
| Vetoed: at least one rejection, and rejections ≥ approvals | any verdict | Failed |
| Did not reach the threshold | uncertain, not delivered, or below 85% | Failed |
In short: a confident agent stands in for missing votes, and a holder rejection beats the agent. If the agent is still working when the window closes, the decision waits up to 15 minutes for its verdict, then the holder rules apply.
The project page shows the approval threshold and live vote counts. Each approved milestone records whether holders or the agent approved it, and an agent approval links to the verdict behind it.
The platform operator can switch the agent to advisory mode. In advisory mode verdicts are still published, but only holder votes approve milestones.
#Voting
Voting is optional, but it's how holders veto, and it's how they earn.
- Who can vote: any wallet holding the project token worth more than $20. If no price is available, holding at least 1,000 tokens qualifies.
- How: approve or reject, with a signed wallet message. There are no transactions and no gas, and each wallet counts once per milestone.
- When: only inside the 24-hour window. Votes outside it do not count.
- Read the verdict first. The agent's summary and checks are public, so a holder can review its reasoning and reject if they disagree.
#Vote rewards
When enabled, every eligible vote cast inside the voting window earns a fixed $SHIP reward. You can claim it from your dashboard.
#6. Release
#Approved: the creator gets paid
An approved milestone becomes claimable 48 hours after it was completed, whether holders or the agent approved it. The creator claims it with a signed message, and the milestone's share of the escrow is transferred on-chain to the creator. Market-cap milestones follow the same claim delay once they are reached.
#Missed: holders get paid
A failed milestone forfeits its share of the escrow, which is split as follows:
| Share | Recipient |
|---|---|
| 50% | Holders who voted on that milestone |
| 45% | $SHIP buyback treasury |
| 5% | $SHIP vote-reward treasury |
The voter share is split by weight. Each voter's weight is their project-token holdings at the time they voted, multiplied by a $SHIP holder multiplier:
$SHIP held | Multiplier |
|---|---|
| Under 100,000 | 1x |
| 100,000 or more | 1.3x |
| 10,000,000 or more | 2x |
When participation weighting is enabled, wallets that vote consistently across recent milestones get a further bonus, and wallets that skip votes get a penalty.
If no eligible holders voted, the voter share goes to the buyback treasury. Voters claim their share from the project page.
#Utilities
- Creator dashboard (
/creator): manage milestones, sweep fees into escrow and claim releases. - Holder dashboard (
/dashboard): track and claim vote rewards and see your$SHIPbalance. - Profiles (
/u/<wallet>): public creator and holder profiles. - Discover: live projects with their escrowed amounts.
- Agent verdicts: the latest verdict for each milestone, with its summary and checks, is public at
/api/commitments/<id>/agent. Whether the agent is on, and in which mode, is at/api/agent/status. - ASD: an opt-in tool for creators. You lock project tokens in a dedicated vault, and a capped daily percentage is sold through Jupiter on a fixed schedule. The creator signs the configuration and can pause it at any time.
- Transparent Bundler: creators declare and verify team wallets, and the platform snapshots their balances daily so holders can see team supply.
#Security Model
- You keep custody. Holders and creators use their own wallets. Voting, completing milestones and claiming are all done with signed messages.
- The agent only approves. It can't fail a milestone, trigger a forfeit, sign a transaction or move funds. Holders can veto any agent approval.
- Hard checks, not promises. An agent approval needs at least one fact the platform verified itself. Text that tries to steer the agent downgrades the verdict instead of helping it.
- Rate-limited and audited. Each milestone gets at most a few agent runs, and every run is recorded with its evidence and written to the audit log.
- Dedicated escrows. Each project's escrow is a platform-managed server wallet (Privy). It is used only for that project's sweeps, releases and forfeits.
- Explicit, audited movements. Every release, claim and forfeit is an on-chain transfer and is written to an audit log.
- Defense in depth. Rate limiting, origin checks, replay protection on signed messages, and wallet-signed admin sessions.
#Scope
| Ship & Commit does | Ship & Commit does not |
|---|---|
| Lock creator fees and release them against milestones | Guarantee that a project will deliver |
| Check delivered work with an agent, against criteria the creator signed | Let the agent take, hold or redirect funds |
| Let holders approve, or veto the agent | Require holders to vote on every milestone |
| Record commitments, votes, verdicts and payouts publicly | Rank or recommend tokens |
Nothing on the platform is investment advice, and an agent verdict is not an audit of the project.
#FAQ
Do I have to vote? No. If the creator delivered and the agent can confirm it, the milestone is approved without you. Vote when you want to reject something, when you disagree with the agent, or to earn vote rewards and a share of forfeits.
What if holders don't show up? That's what the agent is for. A milestone that doesn't reach the holder threshold is still approved if the agent is confident it was delivered and no holder vetoed it.
What if the agent gets it wrong? Holders can reject during the vote window, and a rejection that matches or outnumbers approvals overrides the agent. If the agent is unsure, it makes no call and the usual holder rules apply.
Can a creator fool the agent? It is built to make that hard. The agent needs at least one hard check that the platform verified itself, GitHub activity only counts if it happened after the milestone was created, and any text in the evidence that tries to instruct the agent downgrades the verdict. Holders can still veto.
Can the agent fail my milestone or take my funds? No. It can only approve. Failures happen only under the holder rules, and only on-chain release and forfeit rules move escrow.
Does Ship & Commit replace pump.fun? No, and that's the point. Tokens launch and trade on pump.fun, so traders find and buy them exactly as they would any other pump.fun token. Ship & Commit adds the escrow, milestones and agent verification that pump.fun doesn't have.
Is delivery guaranteed? No. The system makes commitments explicit and enforceable: an unshipped milestone costs the creator its share of the escrow.
Do I need $SHIP to vote?
No. You only need to hold the project's token. Holding $SHIP increases your share of forfeited funds.
Can a creator withdraw escrow early? No. Escrow is released only for approved milestones after the claim delay.
